A massive online fraud network known as DoppelCart operates more than 119,000 fake stores designed to steal payment card information.

Most of the fraudulent domains use the .SHOP top-level domain. In fact, the network accounts for approximately 2.72 percent of all websites registered under that domain extension.

German cybersecurity company Nebty discovered the operation. It describes DoppelCart as the largest publicly documented fake-shop network based on its number of domains.

The network is considerably larger than BogusBazaar, another major online shopping fraud operation. BogusBazaar reportedly operated around 75,000 sites and generated an estimated 850,000 fraudulent transactions.

More than 105,000 fake stores remain active

Nebty’s latest scans indicate that more than 105,000 DoppelCart fake shops are still online.

Despite their large number, the stores appear to rely on a relatively small amount of shared infrastructure. According to Nebty, 96 percent of the confirmed sites use identical build files and connect to just 27 commerce backends.

This centralised structure allows the operators to create and manage thousands of fraudulent stores efficiently. It may also help them replace domains quickly when hosting companies or security providers remove individual sites.

The fake stores often look convincing because they impersonate established businesses. Their operators copy product catalogues, descriptions, logos, branding and photographs from legitimate websites.

In some cases, the fraudulent sites load images and other assets directly from the servers of the companies they imitate.

Thousands of brands impersonated

Researchers found that the DoppelCart network mimics 44,182 different brands. The median number of copies is two stores per brand, although some businesses have been targeted far more heavily.

Several popular consumer brands have each been copied by more than 30 fraudulent stores.

To attract shoppers, the sites frequently advertise large discounts. Some products appear to be reduced by as much as 65 percent, creating a sense of urgency for customers looking for bargains.

However, the stores do not exist to fulfil orders. Instead, their checkout pages collect payment and personal information entered by victims.

Checkout pages steal card details

Nebty tested several checkout pages associated with the network and found code designed to harvest sensitive customer data.

The stolen information can include:

  • Payment card numbers
  • Expiration dates
  • Card security codes
  • Cardholder names
  • Email addresses
  • Telephone numbers
  • Home and delivery addresses

The checkout system sends each field to an attacker-controlled command-and-control server through WebSocket connections. Consequently, criminals can receive the information in real time while the victim completes the payment form.

The malicious checkout process can also capture one-time verification codes issued by banks. Attackers may use these codes to approve fraudulent transactions and bypass additional payment protections.

Legitimate companies face customer complaints

Some DoppelCart fake shops display the genuine customer-support details of the brands they impersonate.

As a result, victims may contact the legitimate business when their purchases fail to arrive. This creates additional problems for affected companies, including customer confusion, reputational damage and increased support requests.

Nebty said it contacted the primary hosting provider associated with the fraudulent stores. However, the company reportedly received no response.

The cybersecurity firm has also created a searchable database that allows organisations to check whether DoppelCart is impersonating their brands.

Consumers should carefully inspect unfamiliar online stores before entering payment information. Extremely large discounts, recently registered domains and unusual checkout behaviour can all indicate a fraudulent shop.

Shoppers should also use payment methods that provide strong fraud protection and regularly review their account activity for unauthorised transactions.


0 responses to “DoppelCart Uses 119,000 Fake Shops to Steal Card Data”